2022-04-22
Added · Updated
Circular CSSF 22/807 updates Circular CSSF 12/552 to incorporate EBA Guidelines on internal governance (EBA/GL/2021/05), joint EBA/ESMA Guidelines on suitability assessment (EBA/GL/2021/06), and ESMA Guidelines on MiFID II compliance function requirements (ESMA35-36-1952). The update adapts Annex I of the original circular to reflect new criteria for evaluating the independence of management body members and integrates compliance function requirements across all establishment activities, including investment services. It also clarifies responsibilities regarding AML/CFT and outsourcing in light of Circular 22/806. The revised circular applies to credit institutions and lending professionals and becomes effective on June 30, 2022.
CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.
CIRCULAR CSSF 22/807
1/4
Circular CSSF
22/807
Update of Circular CSSF 12/552, as amended by Circulars CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759 and 21/785 regarding central administration, internal governance and risk management
CIRCULAR CSSF 22/807
2/4
Circular CSSF 22/807
Concerns: Update of Circular CSSF 12/552, as amended by Circulars CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759 and 21/785 regarding central administration, internal governance and risk management
Dear Sirs, Madams,
By this Circular, the CSSF, in its capacity as competent authority, complies with the guidelines of the European Banking Authority listed in point 2 below. The CSSF integrates these guidelines into its administrative practice and regulatory approach to promote the convergence of supervisory practices in this area at the European level.
The following guidelines are concerned:
(1) The amended guidelines of the European Banking Authority on internal governance (Guidelines on internal governance, "EBA/GL/2021/05"); (2) The amended joint guidelines of the European Banking Authority and the European Securities and Markets Authority on the assessment of the suitability of members of the management body and key function holders (Guidelines on the assessment of the suitability of members of the management body and key function holders, "EBA/GL/2021/06"), as published on the website of the European Banking Authority (https://www.eba.europa.eu/joint-esma-and-eba-guidelines-assessment-suitability-members-management-body-revised), and (3) The guidelines of the European Securities and Markets Authority on certain aspects of MiFID II relating to the requirements of the compliance function (Guidelines on certain aspects of MiFID II compliance function requirements, "ESMA35-36-1952").
The EBA/GL/2021/05 guidelines on internal governance have been incorporated into Circular CSSF 12/552 on central administration, internal governance and risk management.
The amended joint guidelines concerning the assessment of the suitability of members of the management body and key function holders from EBA/GL/2021/06 are directly applicable to the establishments defined by the updated Circular CSSF 12/552 (hereinafter referred to as "establishment(s)"). Annex I of the amended Circular CSSF 12/552, which reproduces in part the criteria for assessing the independence of members of the management body contained in paragraph 9.3 of EBA/GL/2021/06, has been adapted.
The main guidelines of ESMA35-36-1952 concerning certain aspects of MiFID II relating to the requirements of the compliance function are integrated into Circular 12/552 by applying them to all activities of the establishment, including the provision of investment services. When implementing these requirements in relation to investment services, establishments take into account the supplementary guidelines formulated in ESMA35-36-1952.
On the occasion of this update, certain other passages of Circular CSSF 12/552 have also been adapted or clarified. This concerns in particular the responsibilities of the compliance function in the field of AML/CFT and the summary report of the compliance function to be provided annually to the CSSF, as well as the requirements regarding outsourcing, to take into account the entry into force of Circular 22/806 on outsourcing.
A version of Circular CSSF 12/552 allowing the changes made to be traced is found in the Annex.
Circular CSSF 12/552, as revised, applies in its entirety to credit institutions, as defined in Article 4, paragraph 1, point 1) of Regulation (EU) 575/2013 of 26 June 2013, including their branches. It also applies to Luxembourg branches of such establishments from third countries, to Luxembourg branches of establishments authorized in another Member State for areas where the CSSF is competent, and in part to professionals carrying out lending operations.
This Circular will be applicable from 30 June 2022.
Claude WAMPACH
Director
Marco ZWICK
Director
Jean-Pierre FABER
Director
Françoise KAUTHEN
Director
Claude MARX
General Manager
Annex
Luxembourg, 22 April 2022
To all credit institutions and professionals carrying out lending operations
CIRCULAR CSSF 22/807
3/4
CIRCULAR CSSF 22/807
4/4
Commission de Surveillance du Secteur Financier 283, route d'Arlon L-2991 Luxembourg (+352) 26 25 1 -1 direction@cssf.lu www.cssf.lu
CIRCULAR CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, AND CSSF 21/785 AND CSSF 22/807 1/97 Circular CSSF 12/552 as amended by the circulars CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, and CSSF 21/785 and CSSF 22/807 Central administration, internal governance and risk management
CIRCULAR CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, AND CSSF 21/785 AND CSSF 22/807 2/97 Circular CSSF 12/552 as amended by Circulars CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, and CSSF 21/785 and CSSF 22/807 Concerns: Central administration, internal governance and risk management 1
Dear Sirs, Madams,
Articles 5(1bis) and 38-1 of the Law of 5 April 1993 on the financial sector ("LSF"), supplemented by CSSF Regulation No. 15-02 on the supervisory and prudential control and assessment process ("RCSSF 15-02"), require credit institutions to have a sound internal governance framework, including in particular a clear organizational structure with a well-defined, transparent and coherent division of responsibilities, effective processes for identifying, managing, controlling and reporting on the risks to which they are or may be exposed, adequate internal control mechanisms, including sound administrative and accounting procedures and remuneration policies and practices that enable and promote sound and effective risk management, as well as control and security mechanisms for their IT systems.
1 For professionals carrying out lending operations, as defined in Article 28-4 of the Law of 5 April 1993 on the financial sector, Chapter 3 of Part III is applicable with the exception of sub-chapter 3.4 "Exposures presenting a particularly high risk". Paragraph 12 of Chapter 2 of Part III is also applicable.
Luxembourg, 22 April 2022
To all credit institutions and professionals carrying out lending operations 1
CIRCULAR CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, AND CSSF 21/785 AND CSSF 22/807 3/97 This Circular specifies the measures that credit institutions must take in implementation of the provisions of the LSF and RCSSF 15-02 regarding central administration, internal governance and risk management. It incorporates European and international principles, guidelines and recommendations applicable in this matter, inscribing them in a proportionate manner in the context of the Luxembourg banking sector.
When, due to the size, nature and complexity of activities and organization, the application of the principle of proportionality requires enhanced central administration, internal governance or risk management, credit institutions refer to the principles set out in Part I, Chapter 2 as well as the guidelines and recommendations listed in Part IV of this Circular to guide this implementation. This applies in particular to the guidelines of the European Banking Authority ("EBA") on internal governance, as updated on 2 July 2021 (Guidelines on internal governance "EBA/GL/2017/11" 2021/05"), and the joint guidelines of the EBA and the European Securities and Markets Authority ("ESMA") on the eligibility of members of management bodies, as updated on 2 July 2021 (Joint ESMA and EBA Guidelines on the assessment of the suitability of members of the management body and key function holders" EBA/GL/2017/12 2021/06").
The principles and best practices arising from other sources already included in previous versions of the Circular are maintained insofar as they have not become obsolete.
Regarding appointments of members of the management body and key function holders, this Circular must be read in parallel with the Prudential Procedure on this matter published on the CSSF website.
The Circular is divided into four parts: the first part contains the scope of application; the second part, the structural requirements regarding central administration and internal governance; the third part, the specific requirements regarding risk management and the fourth part, the entry into force and the chronology of updates allowing the reader to trace the modifications made by successive updates.
CIRCULAR CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, AND CSSF 21/785 AND CSSF 22/807 4/97
TABLE OF CONTENTS
Part I. Definitions and scope of application 7
Chapter 1. Definitions and abbreviations 7
Chapter 2. Scope of application and
proportionality 9
Part II. Framework for central administration
and internal governance 12
Chapter 1. Central administration 12
Chapter 2. The internal governance framework 12
Chapter 3. Generic properties of a "sound"
framework for central administration and internal governance 14
Chapter 4. Supervisory body and authorized management 15
Sub-chapter 4.1. The supervisory body 15
Section 4.1.1. Responsibilities of the supervisory body
15
Section 4.1.2. Composition and qualification of the supervisory body
20
Section 4.1.3. Organization and functioning of the supervisory body
22
Section 4.1.4. Specialized committees 23
Sub-section 4.1.4.1. The audit committee 24
Sub-section 4.1.4.2. The risk committee 26
Sub-chapter 4.2. The authorized management 27
Section 4.2.1. Responsibilities of the authorized management 27
Section 4.2.2. Qualification of the authorized management 31
Chapter 5. Administrative, accounting and IT organization 32
Sub-chapter 5.1. The organizational chart and human resources 32 Sub-chapter 5.2. Procedures and internal documentation 33 Sub-chapter 5.3. The administrative and technical infrastructure 34
Section 5.3.1. The administrative infrastructure of commercial functions 34
Section 5.3.2. The financial and accounting function 34
Section 5.3.3. The IT function 36
Section 5.3.4. The internal and external communication and alert system 37
Section 5.3.5. The crisis management system 37
Chapter 6. Internal control 38
Sub-chapter 6.1. Operational controls 39
Section 6.1.1. Daily controls carried out by
operating staff 39
Section 6.1.2. Continuous critical controls 39
CIRCULAR CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, AND CSSF 21/785 AND CSSF 22/807 5/97
Section 6.1.3. Controls carried out by members of the
authorized management on activities or functions falling under their direct responsibility 40 Sub-chapter 6.2. Internal control functions 41
Section 6.2.1. Generic responsibilities of internal control functions 41
Section 6.2.2. Characteristics of internal control functions 42
Section 6.2.3. Execution of internal control functions' work 43
Section 6.2.4. Organization of internal control functions 45
Section 6.2.5. The risk control function 49
Sub-section 6.2.5.1. Scope and specific responsibilities of the risk control function 49 Sub-section 6.2.5.2. Organization of the risk control function 51
Section 6.2.6. The compliance function 52
Sub-section 6.2.6.1. The compliance charter 52 Sub-section 6.2.6.2. Scope and specific responsibilities of the compliance function 53 Sub-section 6.2.6.3. Organization of the compliance function 56
Section 6.2.7. The internal audit function 56
Sub-section 6.2.7.1. The internal audit charter 56 Sub-section 6.2.7.2. Specific responsibilities and scope of application of the internal audit function 58 Sub-section 6.2.7.3. Execution of internal audit work 59 Sub-section 6.2.7.4. Organization of the internal audit function 60
Chapter 7. Specific requirements 61
Sub-chapter 7.1. Organizational structure and legal entities ("Know-your-structure") 61
Section 7.1.1. Complex structures and unusual or
potentially non-transparent activities 62
Sub-chapter 7.2. Conflict of interest management 63
Section 7.2.1. Specific requirements regarding conflicts
of interest related to related parties 64
Section 7.2.2. Documentation of loans granted to
members of the management body and their related parties 65 Sub-chapter 7.3. New Product Approval Process 66 Sub-chapter 7.4. Outsourcing 67
Chapter 8. Legal reporting 75
CIRCULAR CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, AND CSSF 21/785 AND CSSF 22/807 6/97
Part III. Risk management 76
Chapter 1. General principles on risk
measurement and management 76
Sub-chapter 1.1. The risk management framework at the establishment level 76
Section 1.1.1. Generalities 76
Section 1.1.2. Specific policies (risk, capital and liquidity policies) 76
Section 1.1.3. Risk identification, management, measurement and reporting 77
Chapter 2. Concentration risks 78
Chapter 3. Credit risk 79
Sub-chapter 3.1. General principles 79
Sub-chapter 3.2. Residential mortgages to individuals 80 Sub-chapter 3.3. Loans to real estate developers 80 Sub-chapter 3.4. Exposures presenting a particularly high risk 81 Sub-chapter 3.5. Non-performing exposures and restructured exposures 82
Chapter 4. Risk Transfer Pricing 83
Chapter 5. Private wealth management ("private banking") 83
Chapter 6. Risks related to shadow banking entities 84
Sub-chapter 6.1. Implementation of sound internal control principles 84 Sub-chapter 6.2. Application of quantitative limits 85
Chapter 7. Asset encumbrance risk 87
Chapter 8. Interest rate risk 88
Sub-chapter 8.1 Interest rate risk inherent to non-trading activities 88 Sub-chapter 8.2. Corrections to the modified duration of debt securities 88
Chapter 9. Risks related to the custody of financial assets by third parties 88
Part IV. Chronology 89
CIRCULAR CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, AND CSSF 21/785 AND CSSF 22/807 7/97
Part I. Definitions and scope of application
Chapter 1. Definitions and abbreviations
The CSSF also retains, as a host authority for Luxembourg branches of credit institutions authorized in another Member State, supervisory responsibility for certain areas not related to prudential banking supervision, namely in particular the fight against money laundering and terrorist financing, the rules applicable to the provision of investment services and the control of obligations applicable to depositaries of Luxembourg UCITS;
From a prudential perspective, the authorized management is responsible for the daily management of an establishment, in accordance with the strategic directions and key policies approved by the supervisory body. In a monistic system, the authorized directors may also be members of the board of directors, whereas in a dualistic system, the authorized management corresponds strictly to the executive board;
2 In accordance with the provisions of Council Regulation (EU) No 1024/2013 of 15 October 2013 ("SSM Regulation") conferring specific tasks on the ECB concerning policies relating to the prudential supervision of credit institutions and of Regulation (EU) No 468/2014 of the European Central Bank establishing the framework for cooperation within the Single Supervisory Mechanism between the European Central Bank, national competent authorities and designated national authorities ("SSM Framework Regulation").
CIRCULAR CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, AND CSSF 21/785 AND CSSF 22/807 8/97
3) "establishment": (i) Luxembourg credit institutions, as defined in Article 4(1)(1) of Regulation (EU) 575/2013 of 26 June 2013 on prudential requirements for credit institutions and investment firms, including their branches, Luxembourg branches of credit institutions from third countries as well as Luxembourg branches of credit institutions authorized in another Member State;
"significant institution": systemically important credit institutions according to Article 59-3 of the LSF and, where applicable, other credit institutions determined by the competent authority based on the assessment of the size and internal organization of the establishments as well as the nature, scale and complexity of their activities;
"management body": the management body, according to the definition of the LSF, corresponds to the management body in its supervisory function and in its executive function according to the EBA guidelines on internal governance (Guidelines on internal governance "EBA/GL/2021/05 2017/11"). It designates the board of directors and the authorized management of an establishment with a monistic organization or the supervisory board and the executive board of an establishment with a dualistic organization;
"supervisory body": the supervisory body corresponds to the management body in its supervisory function according to the EBA guidelines on internal governance (Guidelines on internal governance "EBA/GL/2021/05 2017/11") and to the members of the management body who do not exercise an executive function within the meaning of the LSF. Financial sector regulation allocates to the boards of directors and supervisory boards of credit institutions responsibilities regarding supervision and control, as well as regarding the determination and approval of strategic directions and guiding principles;
"related parties":
a. legal entities (structures) belonging to the group to which the establishment belongs; as well as b. personnel, shareholders;
c. members and members of the management body and senior management of these entities the establishment or of the entities mentioned in point a., their spouses or registered partners in accordance with applicable national law and their children and parents;
CIRCULAR CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, AND CSSF 21/785 AND CSSF 22/807 9/97 d. commercial entities in which a member of the management body or senior management, or a close family member as referred to in point c., holds a qualifying holding representing at least 10% of the capital or voting rights, in which these persons can exercise significant influence or in which these persons hold positions within the general management or the management body;
"Prudential Procedure": prudential procedure for the appointment of members of the management body and key function holders at credit institutions;
"key function holders": the heads of functions whose exercise allows for significant influence on the conduct or control of the activities of establishments. They include in particular the heads of the three internal control functions at all establishments, namely: the Chief Risk Officer ("CRO") for the risk control function, the Chief Compliance Officer ("CCO") for the compliance function and the Chief Internal Auditor ("CIA") for the internal audit function, as well as the head of the financial function (Chief Financial Officer, "CFO") at significant institutions. Establishments may identify other key function holders based on a risk-based approach;
ESG: Environmental, Social and Governance (Risk);
CEBS: Committee of European Banking Supervisors;
CRD IV: Directive 2013/36/EU of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, as amended amending Directive 2002/87/EC and repealing Directives 2006/4...
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 262,148-character original (9% of the document). The remainder was not translated. The complete original-language text is stored with this document.]
Read the rest free
Amended 1 time · last 2024-08-29
This document amends: Circular CSSF 20/750 on ICT and Security Risk Management Requirements
Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CSSF
CSSF published 3 documents in the last 30 days. We email you each new one the day it's published.